Ransom

Generic.Ransom.Xorist.3BBBE28A (file analysis)

Malware Removal

The Generic.Ransom.Xorist.3BBBE28A is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Generic.Ransom.Xorist.3BBBE28A virus can do?

  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Mimics the file times of a Windows system file
  • Installs itself for autorun at Windows startup
  • Exhibits possible ransomware file modification behavior
  • Network activity detected but not expressed in API logs
  • Creates a copy of itself

How to determine Generic.Ransom.Xorist.3BBBE28A?


File Info:

crc32: 9B1AF996
md5: e8f4e6f27eb7fc50e1815863bfecc163
name: E8F4E6F27EB7FC50E1815863BFECC163.mlw
sha1: a79141784ff69ae5df4d9fab9bc1a6e959b87000
sha256: 93df54db83227e64888c37dbf46655fe6791a16e9755ac065028942ef9c75b97
sha512: 0785fd9ad2ebadfce493e04b4ae6503b7c82ccb8ac1a5d021e49f8a78fae9d70282061da33341055320e266b8af9aaaf55d35517ca111ed2eef316d043d1bd78
ssdeep: 12288:F5rr+cwzkxO9tRcY7j1x832IVpdFkvLn8Lfd1:F5X+cWkuvRN+GXvLU1
type: PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed

Version Info:

0: [No Data]

Generic.Ransom.Xorist.3BBBE28A also known as:

BkavW32.AIDetect.malware1
K7AntiVirusTrojan ( 005451b81 )
Elasticmalicious (high confidence)
DrWebTrojan.Encoder.94
CynetMalicious (score: 100)
CAT-QuickHealRansom.Genasom.FO4
ALYacGeneric.Ransom.Xorist.3BBBE28A
CylanceUnsafe
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_60% (D)
K7GWTrojan ( 005451b81 )
Cybereasonmalicious.27eb7f
BaiduWin32.Trojan.Filecoder.g
CyrenW32/Filecoder.Y.gen!Eldorado
SymantecRansom.CryptoTorLocker
ESET-NOD32a variant of Win32/Filecoder.Q
APEXMalicious
AvastWin32:Dh-A [Heur]
ClamAVWin.Trojan.CryptoTorLocker2015-1
KasperskyTrojan-Ransom.Win32.Xorist.gf
BitDefenderGeneric.Ransom.Xorist.3BBBE28A
NANO-AntivirusTrojan.Win32.Xorist.rhtgz
ViRobotTrojan.Win32.A.Xorist.504320[UPX]
MicroWorld-eScanGeneric.Ransom.Xorist.3BBBE28A
TencentTrojan.Win32.CryptoTorLocker2015.a
Ad-AwareGeneric.Ransom.Xorist.3BBBE28A
SophosTroj/Ransom-EY
ComodoTrojWare.Win32.Kryptik.ER@4o1ar2
BitDefenderThetaGen:NN.ZexaF.34758.GmGfaWI0NGni
VIPRETrojan.Win32.Ransom.fo (v)
TrendMicroRansom_XORIST.SMA
McAfee-GW-EditionGenericRXGV-DA!303059FBD9EC
FireEyeGeneric.mg.e8f4e6f27eb7fc50
EmsisoftGeneric.Ransom.Xorist.3BBBE28A (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojan/Generic.xupo
AviraHEUR/AGEN.1114186
eGambitUnsafe.AI_Score_100%
MicrosoftProgram:Win32/Wacapew.C!ml
ArcabitGeneric.Ransom.Xorist.3BBBE28A
GDataGeneric.Ransom.Xorist.3BBBE28A
TACHYONTrojan/W32.Agent.1854976.N
AhnLab-V3Trojan/Win32.Xorist.R61245
McAfeeArtemis!E8F4E6F27EB7
MAXmalware (ai score=89)
VBA32BScope.TrojanRansom.Xorist
PandaTrj/CI.A
TrendMicro-HouseCallRansom_XORIST.SMA
RisingMalware.Heuristic!ET#96% (RDMK:cmRtazrgX1SV2frQ15g5RGp5iHxd)
YandexTrojan.GenAsa!BiN1E6e8pFA
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Xorist.DD8C!tr.ransom
AVGWin32:Dh-A [Heur]

How to remove Generic.Ransom.Xorist.3BBBE28A?

Generic.Ransom.Xorist.3BBBE28A removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment